T09 · Insecure Skill Coding Practices
- Location
scripts/videogen.py:190- Finding
API Key Disclosure Through Untrusted Video Download URLs
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a coherent AI video-generation skill, but it needs review because its script can expose the API key during video downloads and its credential guidance is weak.
Install only if you are comfortable sending video prompts and parameters to redfox.hk/upstream video providers. Prefer REDFOX_API_KEY in your environment over --api-key or plaintext config files, avoid sensitive or regulated content in prompts, and review/fix the download-session and filename-prefix issues before using this in a higher-trust environment.
scripts/videogen.py:190API Key Disclosure Through Untrusted Video Download URLs
scripts/videogen.py:190Path Traversal Through the User-Controlled Output Filename Prefix
SKILL.md:167API Key Exposure Through Command-Line Arguments and Insecure Configuration Guidance
The README’s invocation guidance is broad and trigger-oriented around generic user intents like '生成…视频' and '查询任务…结果', without clear boundaries for when this skill should or should not be selected. In an agentic environment, that can cause over-invocation on loosely related prompts, leading to unintended external API calls, unnecessary spend, and possible transmission of user-provided sensitive text to a third-party video service.
The skill declares no explicit tool scope even though its documentation clearly indicates access to environment variables, local file reads, and outbound network calls. Without a declared permission boundary, an agent platform may invoke the skill with broader capabilities than users expect, increasing the chance of unintended secret access or data egress.
The activation text uses broad trigger terms like 'AI 视频' and 'text-to-video', which can cause the skill to be selected for loosely related user requests. Overbroad routing increases the risk that prompts or files are sent to this third-party workflow when the user did not intend to use it.
Although the document mentions redfox.hk and the underlying model provider, it does not give a clear privacy warning that user prompts and generated media are transmitted to third-party services. Users may disclose sensitive prompts or business content without informed consent, leading to unintended external data exposure.
The documentation recommends passing API keys on the command line and storing them in a plaintext JSON file, but does not warn that command-line arguments can end up in shell history and process listings and that plaintext files may be readable by other local users or backups. This increases the chance of credential leakage and later unauthorized API use.
The skill explicitly instructs users to persist the API key in a plaintext file under ~/.qoder/apis/redfox.json for reuse across sessions. Persistent plaintext secret storage expands the exposure window: other local processes, users, backup systems, or malware can recover the credential long after initial setup.
|----------|------|------|
| **环境变量**(推荐) | 设置一次,全局生效 | `export REDFOX_API_KEY=ak_你的密钥` |
| **命令行参数** | 临时使用,单次生效 | `python3 "$SKILL_PATH/scripts/videogen.py" "prompt" --api-key ak_你的密钥` |
| **配置文件** | 持久化存储,跨会话保留 | `mkdir -p ~/.qoder/apis && echo '{"api_key":"ak_你的密钥"}' > ~/.qoder/apis/redfox.json` |
---
This code file contains natural-language strings and usage text in Chinese, including the module description and command examples, while not offering any language-selection mechanism. Under the policy rule, forcing a specific language without user opt-in is a natural-language policy violation.
The confirmation prompt and many user-facing CLI messages are emitted only in Chinese, which constrains interaction to a single language without opt-in. Because the file does not offer a locale choice or document a justified region-specific restriction, this conflicts with the language policy requirement.
No suspicious patterns detected.